The details on how it works from the website for those reading this chain.
"how does this work
k-id, the age verification provider discord uses doesn't store or send your face to the server. instead, it sends a bunch of metadata about your face and general process details. while this is good for your privacy (well, considering some other providers send actual videos of your face to their servers), its also bad for them, because we can just send legitimate looking metadata to their servers and they have no way to tell its not legitimate.
while this was easy in the past, k-id's partner for face verification (faceassure) has made this significantly harder to achieve after amplitudes k-id verifier was released, (which doesn't work anymore because of it.)
with discord's decision of making the age verification requirement global, we decided to look into it again to see if we can bypass the new checks.
step 1: encrypted_payload and auth_tag
the first thing we noticed that the old implementation doesn't send when comparing a legitimate request payload with a generated one, is its missing encrypted_payload, auth_tag, timestamp and iv in the body.
looking at the code, this appears to be a simple AES-GCM cipher with the key being nonce + timestamp + transaction_id, derived using HKDF (sha256). we can easily replicate this and also create the missing parameters in our generated output.
step 2: prediction data
heres where it kind of gets tricky, even after perfectly replicating the encryption, our verification attempt still doesn't succeed, so they must also be doing checks on the actual payload.
after some trial and error, we narrowed the checked part to the prediction arrays, which are outputs, primaryOutputs and raws.
turns out, both outputs and primaryOutputs are generated from raws. basically, the raw numbers are mapped to age outputs, and then the outliers get removed with z-score (once for primaryOutputs and twice for outputs).
there is also some other differences:
XScaledShiftAmt and yScaledShiftAmt in predictions are not random but rather can be one of two values
It is checked that the media name (camera) matches one of your media devices in the array of devices
It is checked if the states completion times match the state timeline
with all of that done, we can officially verify our age as an adult. all of this code is open source and available on github, so you can actually see how we do this exactly."
No just voice channels, I'm glad they have them but it was completely missing from their marketing on the website. Just says "text channels done right" and there isn't a single line about voice support
Edit, found a reddit post from about a month ago which is copied below. So it looks like it barely supports voice so far.
"Apparently The voice chat feature has been brought back in stoat
It only works in the desktop version though. Mobile devices you're going to have to wait a bit longer though.
Otherwise the quality of it is really really good but you will experience a massive delay in your voice being sent through the voice medium. It's about 800 millisecond delay even with the fastest speeds. But at least it's something.
"
"oh great, competition in a market with no competition. Horrible."
Intel has already been making discrete GPUs for two generations and they are very cheap and aren't the most performant but fantastic for the price.
I'd rather a non-US player enter the market like moorethreads, but because of us capitalist assholes, handicapping China competition for a long time they aren't going to be able to make cards that are up to our performance standards till the 2030s probably
The original comment said Google, instead of Bezos, I have no idea why they edited their comment to this. Maybe they are thinking of Microsoft, who recently handed over encryption keys, but they don't make phones anymore, lol.
As another said, a Pixel with Graphene OS is likely the most secure device you can have, even against an Apple product. Cellebrite, the software a lot of governments use to break into these phones can't get into a Pixel device before first unlock with Graphene OS. I believe a number of Apple products are the same thing as they can't be accessed before first unlock or lockdown mode, but your data is more secure in the hands of an open source developer than a massive capitalist company.
Also, a notable feature of GrapheneOS is automatic reboots after no use for any arbitrary time value you want, so your phone will always be in a "before first unlock" state if some steals it like the government. They also have lockdown mode as well, not sure how that works technically on Android beyond disabling biometrics.
Im pretty into self hosting and have a number of public facing services like 4get and SearXNG, those two don't use that much data. Also host immich for myself and family to replace Google Photos. Some of the bigger data hogs.
Archive warrior - I run a Docker container that constantly scrapes, compresses, and uploads whatever data the internet archive team wants most. I've had it running for a couple years now and they've had me scraping Telegram. That does a couple hundred gigs a month.
I2P Router - The invisible internet project, it's sort of like Tor, but in my opinion more secure and better because it uses garlic routing instead of more centralized servers. Although it's way less popular than Tor and seems most people use it for torrenting. Either way, I recently started hosting a router because governments around the world are cracking down on freedom of speech and censoriship, and increasing their surveillance powers. So I want to support the network and help it grow, this by itself does ~1TB of upload and download a month. Everyone in the world should start pivoting to more secure and decentralized internet solutions like this. Fuck the government.
Linux ISOs torrents - I love Linux, what can I say?
Backup server - I have an off-site Raspberry Pi backup server at my friend's house that I do nightly backups of my important data to. So just depending on how much I've built up since the last backup that can be modest in size.
Otherwise we have a sort of high bandwidth household with video content consumption.
I paid $180 a month for unlimited data on cox, but they threatened to terminate my account after I passed 1tb of upload in a month, they were calling and telling me it's a violation of their terms of service. I said I pay for fucking unlimited data, "that doesn't include upload" you scummy little fucks, false fucking marketing in that case because you advertised UNLIMITED DATA.
I lucked out when I bought a house that has quantum fiber, I pay $50 a month for 500/500 and real unlimited. I push 4 - 8 tb of usage per month with about half being upload.
Unifi Ubiquiti products are one of the best option for completely local data hosting and camera services with really good "ai" detections all run locally, but they aren't that cheap and you'll need to buy one of their Unifi protect capable routers to get started, which is gonna be like $300 by itself.
Edit: Looks like they have a standalone recorder with a 3.5 inch drive bay but it's still $200, and also most of their cameras are Ethernet. They do have a couple wireless options but not many.
The thing is, the professor literally didn't say anything. He posted two photos. One was a headline with the Charlie Kirk quote, and one was about his death.
Servo is advertised, atleast what I've seen, as a lightweight browser for embedded devices. I'm hyped for ladybird, and servo if it Is going to be focused on more than low power devices
It is what it is. I do personally use LLMs because I recognize it is a tool that is actually good at some things, for instance, cursory research on something I'm working on that can get me a general idea of the knowledge I should be looking into to get the task done. Key aspect being I need to do all the follow up research from real sources to gather more data, and of course verify the assumptions from the LLM.
The problem is people taking the word of the actually incredibly cool (on a math level) next best token generator as the truth of God. Its dumb people doing dumb things, problem is dumb people imo.
Edit: I guess that's sort of harsh. There should also just be some better education from the people making these tools on the problems and correct ways to use them.
It's the hype thing to do right now for web browsers, and Firefox is already way behind. I know it may be hard to believe if you only browse Lemmy (like myself), but the average person actually likes these so-called "AI" tools or at least a significant amount of them do.
So Firefox needs to try and attract more normies from chrome, a lot of these "normal" people would be more likely to switch for that 'one killer ai feature".
Also imo we should all be ready to switch to Ladybird when the first version comes out, I know I'll be running the Alpha. If you don't know Ladybird is a brand new browser written from the ground up, it's also open source. https://ladybird.org/
Honestly, no clue. Probably not. You're right, they have a big obstacle in the way of becoming profitable if they aren't because they only operate in certain areas they have a lot of training data for.
Waymo self driving cars are very good imo, I live near a location where they operate and drive along side them daily on my way to work and have ridden in one twice. They are way better than human drives in my area.
The details on how it works from the website for those reading this chain.
"how does this work
k-id, the age verification provider discord uses doesn't store or send your face to the server. instead, it sends a bunch of metadata about your face and general process details. while this is good for your privacy (well, considering some other providers send actual videos of your face to their servers), its also bad for them, because we can just send legitimate looking metadata to their servers and they have no way to tell its not legitimate. while this was easy in the past, k-id's partner for face verification (faceassure) has made this significantly harder to achieve after amplitudes k-id verifier was released, (which doesn't work anymore because of it.)
with discord's decision of making the age verification requirement global, we decided to look into it again to see if we can bypass the new checks. step 1: encrypted_payload and auth_tag
the first thing we noticed that the old implementation doesn't send when comparing a legitimate request payload with a generated one, is its missing encrypted_payload, auth_tag, timestamp and iv in the body.
looking at the code, this appears to be a simple AES-GCM cipher with the key being nonce + timestamp + transaction_id, derived using HKDF (sha256). we can easily replicate this and also create the missing parameters in our generated output. step 2: prediction data
heres where it kind of gets tricky, even after perfectly replicating the encryption, our verification attempt still doesn't succeed, so they must also be doing checks on the actual payload.
after some trial and error, we narrowed the checked part to the prediction arrays, which are outputs, primaryOutputs and raws.
turns out, both outputs and primaryOutputs are generated from raws. basically, the raw numbers are mapped to age outputs, and then the outliers get removed with z-score (once for primaryOutputs and twice for outputs).
there is also some other differences:
XScaledShiftAmt and yScaledShiftAmt in predictions are not random but rather can be one of two values It is checked that the media name (camera) matches one of your media devices in the array of devices It is checked if the states completion times match the state timeline
with all of that done, we can officially verify our age as an adult. all of this code is open source and available on github, so you can actually see how we do this exactly."